Back to Blog
Case Studies5 min readNov 5, 2024

Case Study: How a Fortune 500 Cut Account Takeovers by 85%

How a Fortune 500 financial services firm cut successful account takeovers by 85% and fraud losses by 86% in six months with credential monitoring.

B

Bob Adams

Threat Analyst at Revealer

Executive Summary

A Fortune 500 financial services company watched account takeovers climb on its digital banking apps. They plugged Revealer.US credential monitoring into the login path. Six months later, successful ATOs were down 85%.

The Challenge

Background

The company operates multiple digital banking platforms serving over 10 million customers. In early 2024, they observed:

  • 340% increase in credential stuffing attacks
  • $2.3M in fraud losses attributed to ATO
  • 45,000 customer accounts compromised in Q1 alone
  • Increasing customer complaints and churn

Root Causes

The investigation pointed at four sources, none of them surprising:

  1. Password reuse: Customers using the same credentials across multiple services
  2. Stealer malware: Customer devices infected with infostealers harvesting credentials. Exposure of this kind shows up in stealer log data long before the fraud does.
  3. Phishing: Sophisticated phishing campaigns targeting customers
  4. Dark web sales: Active trading of their customer credentials on underground forums

Previous Defenses

The company had implemented standard defenses:

  • Rate limiting on login endpoints
  • Device fingerprinting
  • Risk-based authentication
  • MFA (optional for customers)

Those controls caught the noisy stuff. They did not catch logins that used real passwords and stolen session cookies, because those look like the customer.

The Solution

Implementation Approach

The security team put Revealer.US in three places, in this order:

Phase 1: Exposure Assessment (Week 1-2)

Initial analysis, run the same way as a data breach lookup, revealed:

  • 127,000 customer email addresses present in breach databases
  • 34,000 credentials with associated passwords
  • 8,500 records in recent device exposures

Phase 2: Proactive Reset Campaign (Week 3-4)

For high-confidence exposures:

  • Forced password resets for 15,000 highest-risk accounts
  • Personalized security notifications explaining the risk
  • Streamlined re-enrollment with MFA incentives

Phase 3: Real-Time Monitoring (Ongoing)

Integrated the Revealer.US API into the authentication flow (see the API documentation for endpoint details):

Login Attempt
     │
     ▼
┌──────────────────┐
│ Standard Auth    │
│ (username/pass)  │
└────────┬─────────┘
         │
         ▼
┌──────────────────┐
│ Revealer.US Check  │◀──── Real-time credential
│ (async lookup)   │      exposure check
└────────┬─────────┘
         │
    ┌────┴────┐
    │ Exposed?│
    └────┬────┘
         │
    Yes  │  No
    ▼    ▼
Step-Up  Normal
Auth     Access

When credentials matched known exposures:

  • Require additional authentication factor
  • Flag session for enhanced monitoring
  • Queue for proactive password reset notification

Results

Six-Month Outcomes

Metric Before After Change
Successful ATO attacks 15,000/month 2,250/month -85%
Fraud losses $380K/month $52K/month -86%
Customer complaints 890/month 145/month -84%
Mean time to detect 18 days 4 hours -99%

ROI Analysis

Annual savings:

  • Fraud reduction: $3.9M
  • Customer service costs: $240K
  • Investigation hours: $180K
  • Total: $4.32M

Investment:

  • Revealer.US subscription: $120K/year
  • Integration development: $85K (one-time)
  • ROI: 35x in first year

Revealer.US pricing runs from a free tier through paid self-serve plans starting at $12.99/mo, with custom Enterprise pricing for deployments at this scale. See pricing for current tiers.

Key Success Factors

1. Reset before the stuffing starts

They pulled exposed credentials out of circulation before the stuffing campaigns hit those accounts.

2. Customer-Friendly Approach

Password reset communications explained the "why" without causing alarm:

"We detected that your email address appeared in a third-party data breach. While our systems were not compromised, we're requiring a password update as a precaution..."

3. Continuous Monitoring

New dumps landed every day, so a credential that was clean on Monday could be in a log by Friday. Revealer.US searches 800+ platforms, public records, and known breach datasets from one query (email, username, phone, name, or address), which is how those fresh hits reached the auth flow the same day.

4. Leave the existing stack in place

Exposure checks sat on top of rate limits, device fingerprinting, and risk-based auth. None of those went away.

Lessons Learned

  1. Count the exposed accounts first: 127,000 emails in breach data is what justified the forced-reset list; without that number, the campaign would have been a guess.
  2. Tell customers why: A reset email that names a third-party breach gets fewer angry tickets than a silent lockout.
  3. Integrate, don't replace: Monitoring fed step-up auth. It did not replace rate limits or device fingerprinting.
  4. Bring numbers to the steering committee: Monthly ATO counts and fraud dollars are what got the subscription renewed.

Conclusion

The 85% drop in successful ATOs, and the $3.9M in annual fraud that went with it, came from resetting exposed passwords and stepping up auth on matches, not from a new WAF rule. Customer complaint volume fell with the fraud.

Note: Revealer.US is not a consumer reporting agency, and its results may not be used for employment, tenant, or credit decisions.


Ready to reduce your organization's account takeover risk? Contact our team for a personalized assessment.

Get started

Ready to check your exposure?

Create a free account and search live sources and known breach datasets.

Create account